Story
September 21, 2026

A $6,500 Hack Has Reopened AI’s Biggest Security Argument

Hacktron’s OpenAI breach is being read two ways: as proof that increasingly capable AI can lower the barrier to serious cyberattacks, and as evidence that the greatest risks still sit inside a small number of powerful AI companies and their infrastructure.

The story began with a routine-looking image upload. On July 25, Hacktron AI researchers found that specially crafted HEIF or HEIC files sent to OpenAI’s community forum could exploit an outdated libheif component used by Discourse, the forum’s software. The bug had been fixed upstream months earlier but was not formally logged as a vulnerability, leaving the affected version in circulation.

Hacktron’s three-person team used Anthropic’s Claude in OpenAI’s bug-bounty program. Its earlier Opus 4.8 model failed to produce a working exploit across several sessions, the researchers said; after Opus 5 was released, they gave it the same task and it succeeded within hours. The team then chained a second flaw to seize ChatGPT and Codex accounts, including an OpenAI employee account connected to the company’s GitHub organization.

The researchers notified OpenAI and Discourse, which patched the issue on July 27. OpenAI awarded Hacktron $6,500 and said the problems had been resolved. But the modest bounty has become a much larger warning: AI-assisted offensive work is getting faster, cheaper and less dependent on rare technical expertise. As Gray Swan chief executive Matt Fredrikson put it, “For $200 a month, anyone can use these tools and hack into a company like OpenAI.”

That reading is reinforced by the researchers’ broader warning that the industry is not ready for the security consequences of its own increasingly powerful technology. The concern is not merely that an elite lab can be breached, but that tools once reserved for highly skilled operators may become widely available.

Yet another camp sees the incident differently. Hugging Face chief executive Clément Delangue argued that, as in biology and cybersecurity, “most of the risk is concentrated and created by the few most powerful labs,” and cast open-source AI as a mitigation rather than the central threat. The OpenAI episode leaves both sides with ammunition: powerful labs remain tempting targets, while the tools capable of testing—and attacking—them are becoming easier to buy.